
Exchange ProxyShell: Domain-Wide Ransomware
An internet-facing Exchange server falls to ProxyShell, dropping ASPX web shells that run as SYSTEM. The attacker re-enables a built-in account, dumps LSASS with a Windows DLL, tunnels out with Plink and FRP, moves laterally over RDP, and encrypts the domain with its own BitLocker and DiskCryptor, no ransomware binary in sight. Work the Exchange logs, the endpoint process tree, and the perimeter traffic to reconstruct the intrusion.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Find the foothold
20Overnight, the internet-facing Exchange server generated web traffic that never belonged to any mailbox user. Work the Exchange/IIS request logs and isolate the external address behind the requests that abused Autodiscover to reach the server's backend PowerShell endpoint.
Name the implant
20The exploitation wrote something into the Exchange web application that the attacker kept coming back to. Identify the file planted in the Exchange OWA auth web tree.
Catch the privileged account
25Through the planted page the attacker gave themselves a durable, privileged way back in using an account that should never be active. Identify the built-in account that was re-enabled and added to local Administrators.
Expose the credential theft
25With SYSTEM on the Exchange box, the attacker stole credentials without dropping a recognizable hacking tool. Identify the file written to disk that holds the harvested credential material.
Trace the tunnel out
20The DMZ Exchange host began initiating outbound sessions it had no business making, to keep the operator connected. Identify the external relay the reverse tunnels reached out to.
Classify the impact
15No ransomware executable was ever found, yet the estate was encrypted end to end. Map the final impact to its MITRE ATT&CK technique.
6 tasks · 125 points total
Training Tools
Skills You'll Build
Requires foundational alert triage skills. Multiple data sources to correlate.
Prerequisites
- Basic understanding of security alerts
- Familiarity with SIEM concepts
- Familiarity with XDR concepts
- Familiarity with Firewall concepts
Ready to investigate?
More Operations
View allZerologon DC takeover → ransomware
An unprivileged phishing foothold becomes a domain-wide ransomware outbreak in hours. The attacker abuses the Zerologon flaw to reset a domain controller's machine-account password, pivots controller-to-controller, and encrypts the estate after gutting the backups. Work the Windows Security log, the endpoint process tree, and the perimeter traffic to reconstruct the takeover.
Hide Your RDP
An internet-facing RDP server at a logistics firm is password-sprayed into, and within hours a RansomHub affiliate dumps credentials, pivots to the domain controller and backup servers, steals finance data over SFTP, and deploys ransomware. Work the authentication records, the endpoint process tree, and the perimeter traffic to reconstruct the intrusion end to end.
Overnight on the DMZ Wiki
Quillon Software publishes its engineering wiki straight to the internet from the DMZ. Overnight the host picked up work nobody rostered: requests that never authenticated, shell activity under a service account, and outbound sessions from a server that normally only talks to its update mirrors. Work the web access logs, the Linux audit trail and the perimeter egress, and reconstruct what reached the host and what left it.